Elastic

Elasticsearch

91 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Veröffentlicht 26.09.2026 20:42:27
  • Zuletzt bearbeitet 06.10.2026 15:31:34

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

  • EPSS 0.41%
  • Veröffentlicht 26.09.2026 20:42:25
  • Zuletzt bearbeitet 29.09.2026 20:20:00

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

  • EPSS 0.41%
  • Veröffentlicht 26.09.2026 20:42:23
  • Zuletzt bearbeitet 29.09.2026 18:42:12

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

  • EPSS 0.41%
  • Veröffentlicht 26.09.2026 20:42:20
  • Zuletzt bearbeitet 29.09.2026 20:15:11

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

  • EPSS 0.41%
  • Veröffentlicht 26.09.2026 20:42:18
  • Zuletzt bearbeitet 29.09.2026 20:19:32

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

  • EPSS 0.41%
  • Veröffentlicht 26.09.2026 20:42:16
  • Zuletzt bearbeitet 01.10.2026 13:17:10

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).

  • EPSS 0.41%
  • Veröffentlicht 26.09.2026 20:42:15
  • Zuletzt bearbeitet 29.09.2026 18:41:14

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).

Medienbericht
  • EPSS 0.19%
  • Veröffentlicht 01.09.2026 19:20:34
  • Zuletzt bearbeitet 02.09.2026 18:50:29

Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed...

  • EPSS 0.21%
  • Veröffentlicht 01.09.2026 19:20:29
  • Zuletzt bearbeitet 02.09.2026 18:50:25

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obta...

Medienbericht
  • EPSS 0.58%
  • Veröffentlicht 01.09.2026 19:20:17
  • Zuletzt bearbeitet 02.09.2026 18:49:54

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execut...